
WP Debugging Security & Risk Analysis
wordpress.org/plugins/wp-debuggingA support/troubleshooting plugin for WordPress.
Is WP Debugging Safe to Use in 2026?
Generally Safe
Score 91/100WP Debugging has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of the 'wp-debugging' plugin v2.12.2 reveals a generally strong security posture in terms of direct code vulnerabilities. There are no identified dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. The limited attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events, further contributes to this. The presence of nonce and capability checks is also a positive indicator of secure coding practices.
However, the plugin's vulnerability history is a significant concern. With two known CVEs, including a high-severity vulnerability and a medium-severity one, the plugin has a track record of security flaws. The fact that the last vulnerability was in early 2022 and there are currently no unpatched vulnerabilities is positive, but it doesn't negate the past issues. The common vulnerability types of Cross-Site Request Forgery (CSRF) and Missing Authorization suggest that past issues may have stemmed from insufficient input validation or access control in certain scenarios, even if the current code analysis doesn't reflect those specific weaknesses.
In conclusion, while the current version of 'wp-debugging' appears to have addressed past security issues and adheres to good coding practices for sanitization and escaping, its historical vulnerability record necessitates a cautious approach. Users should remain vigilant and ensure the plugin is always updated to the latest version to benefit from any subsequent security patches.
Key Concerns
- High severity vulnerability historically
- Medium severity vulnerability historically
- Plugin has known historical CVEs
WP Debugging Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Debugging <= 2.11.7 - Cross-Site Request Forgery
WP Debugging <= 2.10.2 - Unauthenticated Plugin Settings Update
WP Debugging Code Analysis
Output Escaping
WP Debugging Attack Surface
WordPress Hooks 6
Maintenance & Trust
WP Debugging Maintenance & Trust
Maintenance Signals
Community Trust
WP Debugging Alternatives
Fullworks Support Diagnostics
fullworks-support-diagnostics
A diagnostic tool that helps plugin developers provide better support by collecting relevant system information and managing debug constants.
Plugin Detective – Troubleshooting Conflicts
plugin-detective
Plugin Detective helps you troubleshoot issues on your site quickly and easily to find the cause of a problem. Once the culprit is found, the problem …
Easy PHP Settings
easy-php-settings
An easy way to manage common PHP INI settings and WordPress debugging constants from the WordPress admin panel.
Config Constants
config-constants
Modify WP_DEBUG and other WordPress constants directly in the WordPress admin rather than manually editing them via wp-config.php!
Development Assistant
development-assistant
Toolkit for debugging and customer support.
WP Debugging Developer Profile
12 plugins · 43K total installs
How We Detect WP Debugging
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-debugging/assets/css/wp-debugging-admin.css/wp-content/plugins/wp-debugging/assets/js/wp-debugging-admin.js/wp-content/plugins/wp-debugging/assets/js/wp-debugging-admin.js/wp-content/plugins/wp-debugging/assets/css/wp-debugging-admin.css?ver=/wp-content/plugins/wp-debugging/assets/js/wp-debugging-admin.js?ver=